What is HEIF Heist?

A bug that could have allowed us to

  • Dump of OpenAI private repositories
  • RCE on Slack which allows leaking files
  • RCE in Meta's core product suite via image upload
  • Leak arbitrary Redacted users' tokens, and AWS access tokens
  • Authenticated RCE on Discourse
  • Unauthenticated RCE in Next.js via AVIF Image Optimization
  • Authenticated RCE on GitHub Enterprise (CVE-2026-19118)
  • RCE on multiple web frameworks/cms.
  • Leak user's files, and sensitive info from multiple applications.

HEIF Heist is Hacktron's name for a class of remote attack paths targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images. By exploiting underlying native libraries, these vulnerabilities allow an attacker to bypass application-level defenses and trigger memory corruption, data exposure, or remote code execution (RCE).